<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Talk standards to me... Oauth 2.1 draft released in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Talk-standards-to-me-Oauth-2-1-draft-released/m-p/34976#M2596</link>
    <description>&lt;P data-unlink="true"&gt;We have a new IETF&amp;nbsp;&lt;A href="https://tools.ietf.org/html/draft-parecki-oauth-v2-1-01" target="_blank" rel="noopener"&gt;draft&lt;/A&gt; for OAuth v2.1, Authorization Framework. It's not radically different from 2.0, but does have the latest security best practices built-in by design. Aaron Parecki had&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;a great &lt;A href="https://aaronparecki.com/2019/12/12/21/its-time-for-oauth-2-dot-1" target="_blank" rel="noopener"&gt;blog&lt;/A&gt; post&amp;nbsp;explaining the rationale behind the update.&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The main changes for your dev teams to be aware of are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Proof Key for Code Exchange (PKCE) is now required for authorization code grant.&lt;/LI&gt;&lt;LI&gt;Exact matching is required for redirect URIs.&lt;/LI&gt;&lt;LI&gt;Refresh tokens are now sender-constrained or one-time use only.&lt;/LI&gt;&lt;LI&gt;Implicit grant and Resource Owner Password Credentials grant have been removed.&lt;/LI&gt;&lt;LI&gt;Bearer tokens in query parameters are no longer allowed.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Image by Aaron Parecki." style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/4034iB45E64B082C7973A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="oauth-maze.png" alt="Image by Aaron Parecki." /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Image by Aaron Parecki.&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 09:30:07 GMT</pubDate>
    <dc:creator>AppDefects</dc:creator>
    <dc:date>2023-10-09T09:30:07Z</dc:date>
    <item>
      <title>Talk standards to me... Oauth 2.1 draft released</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Talk-standards-to-me-Oauth-2-1-draft-released/m-p/34976#M2596</link>
      <description>&lt;P data-unlink="true"&gt;We have a new IETF&amp;nbsp;&lt;A href="https://tools.ietf.org/html/draft-parecki-oauth-v2-1-01" target="_blank" rel="noopener"&gt;draft&lt;/A&gt; for OAuth v2.1, Authorization Framework. It's not radically different from 2.0, but does have the latest security best practices built-in by design. Aaron Parecki had&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;a great &lt;A href="https://aaronparecki.com/2019/12/12/21/its-time-for-oauth-2-dot-1" target="_blank" rel="noopener"&gt;blog&lt;/A&gt; post&amp;nbsp;explaining the rationale behind the update.&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The main changes for your dev teams to be aware of are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Proof Key for Code Exchange (PKCE) is now required for authorization code grant.&lt;/LI&gt;&lt;LI&gt;Exact matching is required for redirect URIs.&lt;/LI&gt;&lt;LI&gt;Refresh tokens are now sender-constrained or one-time use only.&lt;/LI&gt;&lt;LI&gt;Implicit grant and Resource Owner Password Credentials grant have been removed.&lt;/LI&gt;&lt;LI&gt;Bearer tokens in query parameters are no longer allowed.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Image by Aaron Parecki." style="width: 400px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/4034iB45E64B082C7973A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="oauth-maze.png" alt="Image by Aaron Parecki." /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Image by Aaron Parecki.&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:30:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Talk-standards-to-me-Oauth-2-1-draft-released/m-p/34976#M2596</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2023-10-09T09:30:07Z</dc:date>
    </item>
  </channel>
</rss>

